OpenSSL Security Update – 29 May 2024

OpenSSL has released a security update to fix a critical vulnerability across multiple OpenSSL versions.

The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected systems by sending a specially crafted request.

OpenSSL Code Execution Vulnerability (CVE-2024-4741):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

Affected versions:

  • OpenSSL version “1.1.1”.
  • OpenSSL versions “3.3, 3.2, 3.1, 3.0”.
Vulnerabilities

CVE-2024-4741

Mitigations

The enterprise should deploy this patch once it is released and after the testing phase is completed.

OpenSSL Security Advisory

References